diff options
author | 2019-12-02 18:55:47 +0100 | |
---|---|---|
committer | 2019-12-06 09:40:37 +0100 | |
commit | c0071438097dd8b1589fd1b261e4eccb2aae9dee (patch) | |
tree | 30254bc9004a958456b41b7440adf5b4d3e8d4dc | |
parent | 27f5ca9d60ce0874034bf46594871902016e2bef (diff) | |
download | buildroot-c0071438097dd8b1589fd1b261e4eccb2aae9dee.tar.gz buildroot-c0071438097dd8b1589fd1b261e4eccb2aae9dee.tar.bz2 |
package/rabbitmq-c: security bump to version 0.10.0
Add additional input validation to prevent integer overflow when parsing
a frame header. This addresses CVE-2019-18609.
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
(cherry picked from commit 63d0762ab72a3536ea2e07ac75327c7556ed72c1)
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
-rw-r--r-- | package/rabbitmq-c/rabbitmq-c.hash | 2 | ||||
-rw-r--r-- | package/rabbitmq-c/rabbitmq-c.mk | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/package/rabbitmq-c/rabbitmq-c.hash b/package/rabbitmq-c/rabbitmq-c.hash index 19fd1cf064..eb57626518 100644 --- a/package/rabbitmq-c/rabbitmq-c.hash +++ b/package/rabbitmq-c/rabbitmq-c.hash @@ -1,3 +1,3 @@ # Locally calculated -sha256 316c0d156452b488124806911a62e0c2aa8a546d38fc8324719cd29aaa493024 rabbitmq-c-0.9.0.tar.gz +sha256 6455efbaebad8891c59f274a852b75b5cc51f4d669dfc78d2ae7e6cc97fcd8c0 rabbitmq-c-0.10.0.tar.gz sha256 94a12c906acb31a66c2c8a6c1b6e46cab52bc5694c5ada2a06d86b05d3d3f422 LICENSE-MIT diff --git a/package/rabbitmq-c/rabbitmq-c.mk b/package/rabbitmq-c/rabbitmq-c.mk index 63e05099d9..e059ff706c 100644 --- a/package/rabbitmq-c/rabbitmq-c.mk +++ b/package/rabbitmq-c/rabbitmq-c.mk @@ -4,7 +4,7 @@ # ################################################################################ -RABBITMQ_C_VERSION = 0.9.0 +RABBITMQ_C_VERSION = 0.10.0 RABBITMQ_C_SITE = $(call github,alanxz,rabbitmq-c,v$(RABBITMQ_C_VERSION)) RABBITMQ_C_LICENSE = MIT RABBITMQ_C_LICENSE_FILES = LICENSE-MIT |